Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 8 Oct 2026, 16:01 UTC. Ordered by latest scan.
Source proves unconsented postinstall mutation of a foreign, global AI-agent control surface, meeting the explicit blocking policy. The verdict rests on the automatic configuration write,...
The inspected source establishes automatic data exfiltration during installation. The security research label does not neutralize the active collection and transmission behavior.
The inspected source establishes unconsented postinstall mutation of a foreign, user-level AI-agent control surface, which meets the supplied blocking policy. The interactive prompt and m...
The inspected installation hook performs unconsented mutation of global agent instructions, meeting the specified blocking rule. Package-owned instruction storage and an opt-out do not ne...